Secure attestation of hardware device
A device comprises a plurality of hardware, HW, modules including a first HW module comprising a Physically Unclonable Function, PUF, the first HW module or the plurality of HW modules being communicated with a requester. The device receives ( 1006 ), from the requester, a request to transmit an output to the requester. It activates ( 1008 ) the PUF, reads a response from the PUF, and adds the response to an output. The device transmits ( 1012 ) the output to the requester, and it receives ( 1002 ) one or more of a firmware, FW, component, a software, SW, component, or a bitstream, BS, component before receiving ( 1006 ) the request from the requester.
1 . A method performed by a system comprising a plurality of hardware modules including a requester module and one or more further modules, each further module including a respective Physically Unclonable Function (PUF), the method comprising the requester module:
for each further module, obtaining a respective joint measurement based on a combination of a hardware output of the further module and a software measurement of the further module, the hardware output being unique to the further module and dependent upon a PUF response generated by the further module responsive to a request sent by the requester module, and the software measurement being a measurement of one or more of a firmware, software or bitstream component associated with the further module; and
using the respective joint measurements in at least one of a boot verification process and a remote attestation process, for verifying a combined hardware and software integrity of each respective further module, wherein verification of the combined hardware and software integrity of each respective further module depends upon comparing the respective joint measurement obtained for each respective further hardware module with a respective trusted joint measurement known for that further hardware module.
2 . The method of claim 1 , wherein the hardware output of each further module includes the PUF response and one or more of metadata and internal measurements of the further module.
3 . The method of claim 1 , wherein each further module outputs the respective joint measurement responsive to the request sent by the requester module, based on using a one-way function or hash having as inputs the respective hardware output and the respective software measurement.
4 . The method of claim 1 , wherein the requester module generates the joint measurement for each further module based receiving the respective hardware outputs from the one or more further modules, performing the respective software measurements for the one or more further modules, and computing the respective joint measurements according to a one-way function or hash.
5 . The method of claim 1 , wherein the one or more further modules includes at least first and second further modules.
6 . The method of claim 1 , wherein the requester module includes protected memory and wherein the method includes the requester module storing the respective joint measurements in the protected memory.
7 . The method of claim 6 , wherein the respective joint measurements are used in a boot verification process and wherein the method further comprises the requester module obtaining and storing the respective trusted joint measurements in a protected memory prior to performance of the boot verification process.
8 . A system comprising a plurality of hardware modules including a requester module and one or more further modules, each further module comprising a respective Physically Unclonable Function (PUF) and wherein the requester module comprises circuitry configured to:
for each further module, obtain a respective joint measurement based on a combination of a hardware output of the further module and a software measurement of the further module, the hardware output being unique to the further module and dependent upon a PUF response generated by the further module responsive to a request sent by the requester module, and the software measurement being a measurement of one or more of a firmware, a software, or a bitstream component associated with the further module; and
use the respective joint measurements in at least one of a boot verification process and a remote attestation process, for verifying a combined hardware and software integrity of each respective further module, wherein verification of the combined hardware and software integrity of each respective further module depends upon comparing the respective joint measurement obtained for each respective further hardware module with a respective trusted joint measurement known for that further hardware module.